PKI Engineer to design, implement, and operate enterprise-grade Public Key Infrastructure (PKI) services with a strong focus on Microsoft Active Directory Certificate Services (AD CS) and Active Directory (AD) integration. Handson implementation and integration knowledge of certificate lifecycle management, CA hierarchy governance, enrollment automation, HSM-backed key protection, CA backup restore, migration and integration with platforms such as Windows Server, Linux, network/security devices, cloud providers, MDM/EPP, and zero-trust tooling. Subject matter expert for cryptographic standards, certificate-based authentication, and PKI security controls across the organization. Required experience: 1. ADCS (Active Directory Certificate Services) 2. Integrate PKI with Active Directory (AD forests/domains, ADCS, AIA/CDP locations, GPOs) 3. Deploy, Configure, Implement, Install, Architecture & Design • Design and maintain enterprise PKI architectures (Root CA, Policy CA, Issuing CA) with offline/air gapped roots, secure key ceremonies, key usage, and issuance workflows and robust CRL/OCSP distribution. • Engineer solutions for mutual TLS, 802.1X (wired/wireless/VPN), device identity, code signing, S/MIME, BitLocker, and disk/volume encryption certs. • Key sizes, algorithms (RSA, ECC and PQC) encryption and hashing. • Implement HSM-backed key storage for CAs and code signing; lead key ceremonies, disaster recovery designs. Operations & Automation • Own certificate lifecycle management (issuance, renewal, revocation) including automation via Intune, GPO/Autoenrollment, SCEP/NDES, ACME, or MDM connectors. • Manage CRL/OCSP publication, monitoring, and availability, design highly available, geo-distributed revocation endpoints. • Implement scripting/automation (PowerShell, APIs) for bulk issuance, inventory, renewal, and drift detection. Enabling separation of duties for secure operation of PKI infrastructure • CA backup, restore renewal and migration strategy Security & Compliance • Apply strong key management practices (FIPS 140-2/140-3), certificate assurance levels, and secure CA hardening baselines. • Regularly perform PKI risk assessments, access reviews, and control testing (e.g., template permissions, EKU misuse, issuance constraints). • Lead root cause analysis and incident response for certificate/PKI-related outages or security events. • Maintain alignment with NIST, CAB Forum, Microsoft Security Baselines, and internal compliance frameworks (e.g., SOX, PCI, HIPAA, ISO 27001) as applicable.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Career Level
Mid Level
Education Level
No Education Listed